pcscd was enabled in hardware/batm3.nix and hardware/upboard.nix, which cannot express "is a reader fitted": upboard.nix is shared by sintra (HID Global OMNIKEY 5022) and tejo (nothing fitted), so tejo inherited pcscd it has no use for, while the douro — with its own hardware file — got none and wedged on every boot. Make it a machine capability instead. services.bitspire.nfc.enable owns pcscd, the two polkit rules and the wedge-recovery unit, and hands the app a BITSPIRE_NFC_ENABLED flag so it doesn't initialise nfc-pcsc at all on a machine with no reader. Per-model truth lives in nfcReaderForModel in flake.nix next to fiatCodeForModel and upgradeWindowForModel, since a shared hardware file can't answer the question. batm3 and sintra are true; douro and tejo flip to true when readers are fitted. The flag goes through the unit's Environment rather than /var/lib/bitspire/.env, because .env is only written when absent — a machine provisioned months ago would never pick up a new value.
122 lines
4.5 KiB
Nix
122 lines
4.5 KiB
Nix
# Tejo (UP Board / UP4000) Hardware Configuration
|
|
# Intel Atom/Celeron boards used in Lamassu Tejo ATM machines.
|
|
# Supports both UP Board and UP4000 variants — udev rules for both
|
|
# are included since they match different kernel paths and don't conflict.
|
|
#
|
|
# Serial port mapping:
|
|
# ttyJ4 = Printer (Nippon NP-2511D-2)
|
|
# ttyJ5 = Validator (iVizion, ID003 protocol)
|
|
# ttyJ7 = Dispenser (Fujitsu F53/F56)
|
|
|
|
{ config, lib, pkgs, ... }:
|
|
|
|
{
|
|
# Serial peripherals (validator/dispenser/printer modules + udev symlinks +
|
|
# console=tty0) are shared with the live ISO via ./upboard-serial.nix.
|
|
imports = [ ./upboard-serial.nix ];
|
|
|
|
boot = {
|
|
loader = {
|
|
systemd-boot.enable = true;
|
|
efi.canTouchEfiVariables = true;
|
|
timeout = 3;
|
|
};
|
|
|
|
initrd.availableKernelModules = [
|
|
"xhci_pci"
|
|
"ahci"
|
|
"usb_storage"
|
|
"sd_mod"
|
|
"sdhci_pci"
|
|
"sdhci-acpi" # UP Board sintra: eMMC controller is ACPI-enumerated, not PCI
|
|
"mmc_block" # creates /dev/mmcblk* block-device nodes
|
|
"i915"
|
|
];
|
|
|
|
# Force-load the eMMC stack in stage 1 so root-by-label resolves before
|
|
# the kernel hands off to switch_root. Without this, initramfs panics
|
|
# with "An error occurred in stage 1 of the boot process" because
|
|
# /dev/disk/by-label/nixos never materialises in time.
|
|
initrd.kernelModules = [
|
|
"sdhci-acpi"
|
|
"mmc_block"
|
|
];
|
|
|
|
kernelModules = [
|
|
"kvm-intel"
|
|
"i2c-dev"
|
|
"spi-dev"
|
|
# Serial modules (usbserial/ftdi_sio/cp210x) → ./upboard-serial.nix.
|
|
];
|
|
|
|
kernelParams = [
|
|
"i915.enable_psr=0"
|
|
# console=tty0 (keeps ttyS4 free for the F56) → ./upboard-serial.nix.
|
|
"quiet"
|
|
"splash"
|
|
];
|
|
};
|
|
|
|
# Disk layout: GPT with ESP + ext4 root (eMMC on UP Board).
|
|
# Labels match what make-disk-image.nix with partitionTableType="efi"
|
|
# produces — ESP for the FAT partition, nixos for the ext4 root. We
|
|
# previously expected `by-label/boot` here and had to manually
|
|
# `fatlabel` the partition post-flash; aligning the label avoids
|
|
# that hand-step on future re-flashes. (douro.nix already uses ESP.)
|
|
fileSystems."/" = {
|
|
device = "/dev/disk/by-label/nixos";
|
|
fsType = "ext4";
|
|
};
|
|
|
|
fileSystems."/boot" = {
|
|
device = "/dev/disk/by-label/ESP";
|
|
fsType = "vfat";
|
|
};
|
|
|
|
hardware = {
|
|
graphics = {
|
|
enable = true;
|
|
extraPackages = with pkgs; [
|
|
intel-media-driver
|
|
libva-vdpau-driver
|
|
libvdpau-va-gl
|
|
];
|
|
};
|
|
enableRedistributableFirmware = true;
|
|
cpu.intel.updateMicrocode = true;
|
|
};
|
|
|
|
powerManagement = {
|
|
enable = true;
|
|
cpuFreqGovernor = "performance";
|
|
};
|
|
|
|
# No pcscd here. This file is shared by sintra (HID Global OMNIKEY 5022
|
|
# fitted) and tejo (no reader), so the reader is declared per model via
|
|
# `nfcReaderForModel` in flake.nix → services.bitspire.nfc.enable.
|
|
|
|
# Disable suspend/hibernate for kiosk
|
|
systemd.targets = {
|
|
sleep.enable = false;
|
|
suspend.enable = false;
|
|
hibernate.enable = false;
|
|
hybrid-sleep.enable = false;
|
|
};
|
|
|
|
# Camera + LED/SPI peripherals. The serial rules (validator/dispenser/printer
|
|
# symlinks + permissions) are shared with the live ISO in ./upboard-serial.nix.
|
|
services.udev.extraRules = lib.mkAfter ''
|
|
# ── Camera devices ─────────────────────────────────────────────────
|
|
SUBSYSTEM=="video4linux", ATTR{index}=="0", KERNELS=="1-5", ATTRS{idVendor}=="0ac8", ATTRS{idProduct}=="0345", SYMLINK+="video-scan"
|
|
SUBSYSTEM=="video4linux", ATTR{index}=="0", KERNELS=="1-2", ATTRS{idVendor}=="0ac8", ATTRS{idProduct}=="0345", SYMLINK+="video-scan"
|
|
SUBSYSTEM=="video4linux", ATTR{index}=="0", KERNELS=="1-6", ATTRS{idVendor}=="0ac8", ATTRS{idProduct}=="0345", SYMLINK+="video-front"
|
|
SUBSYSTEM=="video4linux", ATTR{index}=="0", KERNELS=="1-3", ATTRS{idVendor}=="0ac8", ATTRS{idProduct}=="0345", SYMLINK+="video-front"
|
|
|
|
# ── LED SPI / peripherals ──────────────────────────────────────────
|
|
KERNEL=="spidev1.0", SYMLINK+="ledspi"
|
|
KERNEL=="spidev2.0", SYMLINK+="ledspi"
|
|
SUBSYSTEM=="spidev", GROUP="spi", MODE="0660"
|
|
SUBSYSTEM=="i2c-dev", GROUP="i2c", MODE="0660"
|
|
SUBSYSTEM=="leds", KERNEL=="upboard:*", ACTION=="add|change", RUN+="${pkgs.findutils}/bin/find /sys$devpath -type f -exec ${pkgs.coreutils}/bin/chmod g+u {} + -exec ${pkgs.coreutils}/bin/chown :leds {} +"
|
|
'';
|
|
}
|